New TAOTH Campaign Exploits End-of-Support Software to Distribute Malware and Collect Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In June 2025, a previously undocumented campaign leveraging end-of-support software began surfacing in telemetry data gathered across Eastern Asia. Dubbed TAOTH, the operation exploits an abandoned Chinese input method editor (IME), Sogou Zhuyin, to deliver multiple malware families. Initial intelligence …

Hackers Weaponize PDF Along With a Malicious LNK File to Compromise Windows Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Attackers have begun leveraging a seemingly innocuous PDF newsletter alongside a malicious Windows shortcut (LNK) file to infiltrate enterprise environments. The attack surfaced in late August 2025, targeting South Korean academic and government institutions under the guise of a legitimate …

Cyber Attacks Targeting Education Sector Surges Following Back-to-School Season

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

As students and staff returned to campuses this August, a stark rise in cyber attacks against educational institutions has been observed worldwide. From January to July 2025, organizations in the education sector endured an average of 4,356 weekly attacks, marking …

Hackers Leverage Compromised Third-Party SonicWall SSL VPN Credentials to Deploy Sinobi Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated ransomware attack has emerged targeting organizations through compromised third-party managed service provider (MSP) credentials, showcasing the evolving tactics of cybercriminals in 2025. The Sinobi Group, operating as a Ransomware-as-a-Service (RaaS) affiliate, successfully infiltrated corporate networks by exploiting SonicWall …

Threat Actors Leveraging Windows and Linux Vulnerabilities in Real-world Attacks to Gain System Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity teams worldwide have observed a surge in sophisticated campaigns exploiting both Windows and Linux vulnerabilities in recent months to achieve unauthorized system access. These attacks often begin with phishing emails or malicious web content designed to deliver weaponized documents. …

Google Confirms Potential Compromise of All Salesloft Drift Customer Authentication Tokens

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has confirmed that a security breach involving the Salesloft Drift platform is more extensive than initially reported, potentially compromising all authentication tokens connected to the service. The new findings from the Google Threat Intelligence Group (GTIG) indicate that the …

DPRK IT Workers Using Code-Sharing Platforms to Secure New Remote Jobs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Over the past year, security researchers have observed a growing trend of North Korean–linked developers establishing credible-looking profiles on popular code-sharing platforms such as GitHub, CodeSandbox, and Gist. These accounts frequently host legitimate open-source projects alongside hidden payloads, allowing operators …

Multiple Hikvision Vulnerabilities Let Attackers Inject Executable Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hikvision has disclosed three significant security vulnerabilities affecting multiple versions of its HikCentral product suite that could enable attackers to execute malicious commands and gain unauthorized administrative access.  The vulnerabilities, assigned CVE identifiers CVE-2025-39245, CVE-2025-39246, and CVE-2025-39247, were reported to …

Virustotal’s New Endpoint Provides Functionality Descriptions for Malware Analysts’ Code Requests

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

VirusTotal today unveiled Virustotal’s New endpoint, which receives code requests and returns a description of its functionality for malware analysts, a powerful addition to its Code Insight platform.  Designed to streamline reverse engineering workflows, the new API endpoint pre-analyzes disassembled or decompiled …

Threat Actors Weaponizing Facebook Ads with Free TradingView Premium App Lures That Delivers Android Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have uncovered a sophisticated malvertising campaign on Meta’s Facebook platform in recent weeks that targets Android users with promises of a free TradingView Premium application. These deceptive ads mimic official TradingView branding and visuals, luring unsuspecting victims to …